30 April 2026
APRA Letter to Industry
APRA called for a step change in AI risk management and governance across all regulated entities, covering banks, insurers, and superannuation trustees. Enforcement action flagged for non-compliance.
Webinar | AI Governance & Cyber Risk
In eight weeks, three authoritative bodies issued AI risk directives aimed squarely at boards and executives across Australia and New Zealand. This webinar cuts through the complexity and tells you exactly what to do before the windows close.
On 23rd June 2026, the heads of five allied cyber security agencies — including Australia's ASD and New Zealand's NCSC — told business leaders the window between AI-accelerated vulnerability discovery and exploitation is shrinking, and the timeline for action is months, not years.
Insicon Cyber Founders, Matt Miller and Greg Bunt explain these directives, and highlight a practial path forward.
The context
None of these are discussion papers. None are optional. Taken together, they represent the clearest signal yet that AI governance has moved from an IT responsibility to a board imperative.
30 April 2026
APRA called for a step change in AI risk management and governance across all regulated entities, covering banks, insurers, and superannuation trustees. Enforcement action flagged for non-compliance.
8 May 2026
ASIC's letter to AFS licensees and market participants must be tabled at every board and risk governance committee. It sets explicit expectations on cyber resilience fundamentals in the AI era.
22 June 2026
The heads of ASD, NCSC NZ, NCSC UK, CISA, and NSA issued a joint statement: AI is accelerating threats at a pace measured in months. Boards and executives are the intended audience.
Webinar agenda
A practical, no-jargon breakdown of every directive, what it requires of your organisation, and the clearest path forward for boards and leadership teams in Australia and New Zealand.
What the joint statement from ASD, NCSC NZ, NCSC UK, CISA, and NSA actually says, why "months not years" is the most important phrase in it, and what it requires of ANZ leadership teams right now.
A detailed walkthrough of what APRA found across regulated entities: AI-specific cyber attack vectors, board literacy expectations, supplier concentration risk, and why point-in-time assurance is no longer adequate for probabilistic AI systems. Plus: the enforcement signal.
ASIC requires its letter to be tabled at every board. We cover what that board conversation should look like, the FIIG Securities enforcement precedent that sets the bar, and how ASIC and APRA's directives work together.
High-risk AI obligations activate 2 August 2026. Extraterritorial reach means ANZ organisations with EU customers or EU-market vendors are already in scope. We explain the practical implications.
How ISO 42001 maps to every framework covered in this webinar. The five questions every board should be asking its leadership team. A practical roadmap for mid-market organisations in Australia and New Zealand. Live Q&A with the Insicon Cyber advisory team.
Audience
This webinar is designed for leaders in regulated sectors across Australia and New Zealand. If AI risk, cyber governance, or regulatory compliance sits anywhere near your agenda, this session is for you.
Understand what APRA and ASIC now expect of you personally and how to discharge your oversight obligations.
Translate the latest regulatory signals into strategic and operational priorities before the compliance windows close.
Get a detailed breakdown of the AI-specific controls APRA, ASIC, and Five Eyes each demand and how they map to your security programme.
Map APRA, ASIC, and Five Eyes requirements to your existing frameworks and identify where the gaps are.
Understand the enforcement posture behind each directive and the extraterritorial exposure your organisation carries under the EU AI Act.
Build the technical case for AI governance investment with your leadership team and understand the controls your organisation needs to implement.
Relevant sectors include financial services, aged care, healthcare, legal, government, and any mid-market organisation deploying or procuring AI systems across Australia and New Zealand.
Your presenters
Co-founder, CEO & Fractional CISO, Insicon Cyber
Matt works directly with boards and executive teams across Australia and New Zealand on AI governance, cyber risk strategy, and regulatory compliance. He has been advising on ISO 42001 and AI security since mid-2025 and is one of the most active practitioners in the ANZ market on frontier AI risk.
Co-founder, Director & Fractional CISO, Insicon Cyber
Greg brings deep expertise in managed compliance, CISO advisory, and operational security across regulated industries. He works hands-on with organisations navigating APRA, ASIC, Essential Eight, ISO 27001, and ISO 42001 obligations across the trans-Tasman region.